Compliance / Free checkFree

  Cookie Banner Checker

Does your cookie banner actually comply?

A free cookie banner checker for UK websites. We load your site in a real browser and test what the banner does, not what it says: whether tracking cookies fire before consent, whether "reject" is as easy as "accept", and whether analytics scripts wait for the click. Graded against PECR and UK GDPR — the rules the ICO actually enforces.

Test your banner

Instant report. No registration required. Part of the full UK GDPR, PECR and accessibility scan.

What we test

Behaviour,
not cosmetics

Most cookie banners are decoration: the tracking fires on page load whatever you click. PECR regulation 6 requires consent before non-essential cookies are set — so the checker loads your site in a headless browser and watches what actually happens.

  • № 01

    Cookies before consent

    We record every cookie set between page load and any interaction with the banner. Analytics, advertising and social pixels in that window are the core PECR breach — "we have a banner" is no defence if Google Analytics fired before anyone touched it. Strictly necessary cookies (session, basket, security) are allowed and scored as such.

  • № 02

    Reject parity

    The ICO's position is that rejecting must be as easy as accepting — a bright "Accept all" beside a buried "manage preferences" maze fails that test. We check whether a reject option exists at the first layer of the banner and flag consent walls that offer no real choice at all.

  • № 03

    The paperwork behind it

    A compliant banner needs a cookie policy that names the cookies, their purposes and lifetimes, and a privacy policy covering the processing behind them. The same scan checks both exist and reads what they cover — because the ICO's first question after "did it consent?" is "did you tell them?".

FAQ

Common
questions

  • Q1

    Do I even need a cookie banner?

    Only if you set non-essential cookies. A site using only strictly necessary cookies — session, security, load balancing — needs no banner at all, and removing an unnecessary one is often the cleanest fix. The moment you add analytics, advertising pixels or embedded social content, PECR requires prior consent.

  • Q2

    Is "implied consent" — continue browsing to accept — still allowed?

    No. UK GDPR's consent standard applies to PECR, and it requires a clear affirmative act — scrolling past a notice or a pre-ticked box doesn't qualify. Banners that say "by continuing you accept cookies" while the cookies are already set are the textbook failure this checker catches.

  • Q3

    Google Analytics loads before consent — does that really matter?

    Yes — it's the most common breach on UK SME sites and exactly what the banner is supposed to prevent. The fix is script gating: the analytics tag must not execute until consent is given, either via your consent platform's blocking feature or Google Consent Mode v2. Pasting the GA snippet directly into the page head defeats both.

  • Q4

    What can the ICO actually do about a bad banner?

    PECR carries fines up to £500,000, and the ICO has been actively writing to UK websites about non-compliant cookie banners since 2023, starting with the biggest and working down. For an SME the realistic first cost isn't the fine — it's failing a customer's supplier due-diligence questionnaire, which increasingly includes cookie compliance.

After the check

Finding the gap is free. So is fixing it.